You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Istio-Ingress Pod证书生成失败及Istiod连接超时问题求助

Istio-Ingress Pod证书生成超时及Webhook请求失败问题排查

问题概述

初始遇到服务连接超时错误:

Error from server (ServiceUnavailable): error trying to reach service: dial tcp 172.44.30.55:15017: connect: connection timed out

通过在EKS节点安全组添加入站规则(来源为EKS集群安全组,允许所有流量和端口)解决上述问题后,出现两个新异常:

1. Istio-Ingress Pod证书生成超时日志

2023-09-10T05:18:55.390302Z     warn    sds     failed to warm certificate: failed to generate workload certificate: create certificate: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing: dial tcp 10.100.19.43:15012: i/o timeout"

2. Istiod Webhook接口请求失败

执行命令:

kubectl get --raw /api/v1/namespaces/istio-system/services/https:istiod:https-webhook/proxy/inject -v4

返回错误响应:

I0909 22:59:29.079159   21513 helpers.go:246] server response object: [{
  "metadata": {},
  "status": "Failure",
  "message": "the server rejected our request for an unknown reason",
  "reason": "BadRequest",
  "details": {
    "causes": [
      {
        "reason": "UnexpectedServerResponse",
        "message": "no body found"
      }
    ]
}]

排查步骤

  • 验证Istiod服务状态

    1. 检查Istiod Pod运行状态:
      kubectl get pods -n istio-system -l app=istiod
      
    2. 确认Istiod服务端点是否就绪,查看Endpoints字段是否包含10.100.19.43:15012:
      kubectl describe svc istiod -n istio-system
      
    3. 查看Istiod Pod日志,排查自身启动或连接异常:
      kubectl logs -n istio-system -l app=istiod --tail=100
      
  • 测试跨Pod网络连通性
    从Istio-Ingress Pod内直接测试到Istiod端点10.100.19.43:15012的连通性:

    kubectl exec -n istio-ingress -it <你的istio-ingress-pod名称> -- curl -v telnet://10.100.19.43:15012
    
  • 检查集群网络策略
    确认没有网络策略限制Istio-Ingress到Istiod的流量:

    kubectl get networkpolicies -A
    

    重点检查是否存在拒绝istio-ingress命名空间向istio-system命名空间发起15012端口请求的规则。

  • 验证Webhook配置

    1. 检查Istio Sidecar注入Webhook的状态:
      kubectl get mutatingwebhookconfiguration istio-sidecar-injector
      
    2. 查看Webhook的服务配置是否正确:
      kubectl describe mutatingwebhookconfiguration istio-sidecar-injector
      
    3. 尝试重启Istiod部署,修复可能的配置异常:
      kubectl rollout restart deployment istiod -n istio-system
      
  • 确认SDS相关配置
    检查Istio-Ingress Pod的环境变量,确认Istiod地址配置正确:

    kubectl exec -n istio-ingress <你的istio-ingress-pod名称> -- env | grep ISTIOD_ADDR
    

内容的提问来源于stack exchange,提问作者Rad4

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 05:10:54